Prepare isolated rootless Gitea Quadlet on Atlas

This commit is contained in:
Fabio Scotto di Santolo
2026-10-01 21:23:40 +02:00
parent 9d0013769c
commit 256d758b1a
9 changed files with 206 additions and 9 deletions

View File

@@ -57,6 +57,8 @@ Ansible-driven personal infrastructure repo for Fedora and Void desktops, Fedora
- Server compose render: `podman-compose -f /opt/docker/server/docker-compose.yml config` and `systemctl status podman-compose-server`
- Atlas media stack:
`ansible-playbook ansible/site.yml --limit atlas --tags storage,sharing,containers --check --diff`
- Atlas rootless Gitea staging (does not start Gitea):
`ansible-playbook ansible/site.yml --limit atlas --tags gitea --check --diff`
- Atlas network/share hardening:
`ansible-playbook ansible/site.yml --limit atlas --tags hardening,sharing --check --diff`
- Atlas ZFS snapshot retention and scrub timers:
@@ -263,9 +265,13 @@ successfully. The first monthly scrub remains a runtime check.
- [x] Design the staged Prometheus-to-Atlas Gitea migration in `docs/atlas-gitea-migration.md`.
The approved topology keeps NPM on Prometheus and moves HTTPS and public SSH (TCP/2222) together;
Gitea must run as a dedicated rootless user Quadlet on Atlas. The rootful-to-rootless data-layout
conversion requires an isolated restore test. No data has been moved or traffic changed.
- [ ] Prepare a separate Atlas Gitea dataset, disabled rootless user Quadlet, and isolated restore test from the
verified Prometheus backup; validate SQLite, repositories, SSH host keys, and target backups.
conversion requires an isolated restore test. No Gitea data has been moved or traffic changed.
- [x] Prepare the dedicated Atlas Gitea dataset, non-login UID/GID 1101 with a separate rootless Podman
sub-ID range, and disabled user Quadlet. On 2026-10-01 the targeted Ansible run and a second idempotent
run passed; the generated unit was inactive, with no staging HTTP/SSH listener. POSIX ACLs on only the
service-namespace parents grant this account traversal without access to sibling datasets.
- [ ] Perform an isolated rootless restore test from the verified Prometheus backup; validate SQLite,
repositories, SSH host keys, and target backups before any traffic cutover.
- [ ] After an explicit outage approval, perform the final consistent copy and HTTPS/SSH cutover,
then remove Gitea from Prometheus' desired stack and backup export without deleting source data.
- [ ] Design and deploy Nextcloud as another explicitly temporary Atlas service before Uranus. Give it